build(deps): refresh governed container image digests

Refresh the pinned digests for the governed node:24-alpine, golang:1.26.8-alpine
and alpine:3.24 tags used by the release, control-plane and mock-github-server
images. Tag versions are unchanged; this picks up the current rebuilt base
layers, matching the docker dependabot policy that refreshes immutable digests
automatically while keeping tag upgrades in explicit work.

Supersedes Dependabot #2104 (node), #2137 (golang) and #2150 (alpine).

Contract-Neutral: digest-only refresh of unchanged governed image tags; no public-contract delta
Change-source: pulse-maintainer
This commit is contained in:
pulse-triage[bot] 2026-09-23 05:23:41 +01:00
parent 9ac6480350
commit bb3951cbb8
3 changed files with 11 additions and 11 deletions

View file

@ -4,7 +4,7 @@ ARG APPRISE_VERSION=1.12.0
# Build stage for frontend (must be built first for embedding)
# Force amd64 platform to avoid slow QEMU emulation during multi-arch builds
FROM --platform=linux/amd64 node:24-alpine@sha256:e67514e5d0f6c46656005e1b693b2ec9d52e80b641307de684d4a015ba7a4eaf AS frontend-builder
FROM --platform=linux/amd64 node:24-alpine@sha256:50c8e8ca1d27439048670df5883f32d57cf81cff6233222c893fd0d9884cbd81 AS frontend-builder
WORKDIR /app/frontend-modern
@ -26,7 +26,7 @@ RUN --mount=type=cache,id=pulse-npm-cache,target=/root/.npm \
# Build stage for Go backend
# Force amd64 platform - Go cross-compiles for all targets anyway,
# and this avoids slow QEMU emulation during multi-arch builds
FROM --platform=linux/amd64 golang:1.26.8-alpine@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS backend-builder
FROM --platform=linux/amd64 golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS backend-builder
ARG BUILD_AGENT
ARG VERSION
@ -213,7 +213,7 @@ RUN --mount=type=cache,id=pulse-go-mod,target=/go/pkg/mod \
# Runtime image for the Docker agent (offered via --target agent_runtime)
FROM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b AS agent_runtime
FROM alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6 AS agent_runtime
# Use TARGETARCH to select the correct binary for the build platform
ARG TARGETARCH
@ -254,7 +254,7 @@ ENTRYPOINT ["/usr/local/bin/pulse-agent"]
# Build the pinned Apprise CLI separately so release runtimes only retain the
# Python interpreter and installed notification dependencies, not pip.
FROM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b AS apprise-builder
FROM alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6 AS apprise-builder
ARG APPRISE_VERSION
@ -265,7 +265,7 @@ RUN apk --no-cache add python3 py3-pip && \
# Base operating-system surface shared by source-built and candidate-assembled
# Pulse server images.
FROM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b AS pulse-runtime-foundation
FROM alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6 AS pulse-runtime-foundation
ARG APPRISE_VERSION
@ -429,7 +429,7 @@ RUN chmod 755 /opt/pulse/scripts/*.sh /opt/pulse/scripts/*.ps1 && \
chown -R pulse:pulse /opt/pulse
# Unified Agent image assembled from the same immutable candidate payload.
FROM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b AS agent_runtime_prebuilt
FROM alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6 AS agent_runtime_prebuilt
ARG TARGETARCH
ARG TARGETVARIANT

View file

@ -1,6 +1,6 @@
# syntax=docker/dockerfile:1.7
FROM --platform=linux/amd64 node:24-alpine@sha256:e67514e5d0f6c46656005e1b693b2ec9d52e80b641307de684d4a015ba7a4eaf AS frontend-builder
FROM --platform=linux/amd64 node:24-alpine@sha256:50c8e8ca1d27439048670df5883f32d57cf81cff6233222c893fd0d9884cbd81 AS frontend-builder
WORKDIR /app/frontend-modern
COPY frontend-modern/package*.json ./
RUN --mount=type=cache,id=pulse-control-plane-npm-cache,target=/root/.npm \
@ -12,7 +12,7 @@ COPY SECURITY.md TERMS.md /app/
RUN --mount=type=cache,id=pulse-control-plane-npm-cache,target=/root/.npm \
npm run build
FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS builder
FROM --platform=$BUILDPLATFORM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder
ARG VERSION=dev
ARG BUILD_TIME=unknown
ARG GIT_COMMIT=unknown
@ -51,7 +51,7 @@ RUN --mount=type=cache,id=pulse-control-plane-go-mod,target=/go/pkg/mod \
-trimpath \
-o /pulse-control-plane ./cmd/pulse-control-plane
FROM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b AS control-plane-runtime-foundation
FROM alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6 AS control-plane-runtime-foundation
RUN apk add --no-cache ca-certificates docker-cli
ENTRYPOINT ["pulse-control-plane"]

View file

@ -1,4 +1,4 @@
FROM golang:1.26.8-alpine@sha256:ce864e7223ac17b1775e6fd0b4c0db580c2eb50e7953a427916379e4b92a1628 AS builder
FROM golang:1.26.8-alpine@sha256:51a7c389a5ddaf82f527191a1e9bff9928655130a44e4975dd1d7e0acf59f1ae AS builder
WORKDIR /build
COPY go.mod ./
@ -7,7 +7,7 @@ RUN go mod download
COPY main.go ./
RUN CGO_ENABLED=0 GOOS=linux go build -o mock-github-server .
FROM alpine:3.24@sha256:28bd5fe8b56d1bd048e5babf5b10710ebe0bae67db86916198a6eec434943f8b
FROM alpine:3.24@sha256:294b683cb724975bec92580e1e685676bd4b50bda910ddb8c51d4cabeaec77e6
RUN apk --no-cache add ca-certificates
WORKDIR /app